This repository was archived by the owner on Nov 28, 2024. It is now read-only.
File tree Expand file tree Collapse file tree 27 files changed +37
-37
lines changed Expand file tree Collapse file tree 27 files changed +37
-37
lines changed Original file line number Diff line number Diff line change 13
13
runs-on : ubuntu-latest
14
14
steps :
15
15
- name : Harden Runner
16
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
16
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
17
17
with :
18
18
egress-policy : audit
19
19
Original file line number Diff line number Diff line change 33
33
runs-on : ubuntu-latest
34
34
steps :
35
35
- name : Harden Runner
36
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
36
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
37
37
with :
38
38
disable-sudo : true
39
39
egress-policy : block
Original file line number Diff line number Diff line change 9
9
runs-on : ubuntu-latest
10
10
steps :
11
11
- name : Harden Runner
12
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
12
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
13
13
with :
14
14
disable-sudo : true
15
15
egress-policy : block
Original file line number Diff line number Diff line change 36
36
steps :
37
37
# Checkout the repository to the GitHub Actions runner
38
38
- name : Harden Runner
39
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
39
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
40
40
with :
41
41
egress-policy : audit
42
42
61
61
62
62
# Upload the SARIF file generated in the previous step
63
63
- name : Upload SARIF results file
64
- uses : github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
64
+ uses : github/codeql-action/upload-sarif@8214744c546c1e5c8f03dde8fab3a7353211988d # v3.26.7
65
65
with :
66
66
sarif_file : results.sarif
Original file line number Diff line number Diff line change 8
8
runs-on : self-ubuntu
9
9
steps :
10
10
- name : Harden Runner
11
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
11
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
12
12
with :
13
13
egress-policy : audit
14
14
Original file line number Diff line number Diff line change 41
41
42
42
steps :
43
43
- name : Harden Runner
44
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
44
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
45
45
with :
46
46
egress-policy : audit
47
47
50
50
51
51
# Initializes the CodeQL tools for scanning.
52
52
- name : Initialize CodeQL
53
- uses : github/codeql-action/init@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
53
+ uses : github/codeql-action/init@8214744c546c1e5c8f03dde8fab3a7353211988d # v3.26.7
54
54
with :
55
55
languages : ${{ matrix.language }}
56
56
# If you wish to specify custom queries, you can do so here or in a config file.
60
60
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
61
61
# If this step fails, then you should remove it and run the build manually (see below)
62
62
- name : Autobuild
63
- uses : github/codeql-action/autobuild@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
63
+ uses : github/codeql-action/autobuild@8214744c546c1e5c8f03dde8fab3a7353211988d # v3.26.7
64
64
65
65
# ℹ️ Command-line programs to run using the OS shell.
66
66
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
73
73
# ./location_of_script_within_repo/buildscript.sh
74
74
75
75
- name : Perform CodeQL Analysis
76
- uses : github/codeql-action/analyze@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
76
+ uses : github/codeql-action/analyze@8214744c546c1e5c8f03dde8fab3a7353211988d # v3.26.7
77
77
with :
78
78
category : " /language:${{matrix.language}}"
Original file line number Diff line number Diff line change 34
34
35
35
steps :
36
36
- name : Harden Runner
37
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
37
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
38
38
with :
39
39
egress-policy : audit
40
40
48
48
uses : microsoft/security-devops-action@73909114be534813fecb63c42f7f95bac57bcb14 # v1
49
49
id : msdo
50
50
- name : Upload results to Security tab
51
- uses : github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
51
+ uses : github/codeql-action/upload-sarif@8214744c546c1e5c8f03dde8fab3a7353211988d # v3.26.7
52
52
with :
53
53
sarif_file : ${{ steps.msdo.outputs.sarifFile }}
Original file line number Diff line number Diff line change 29
29
runs-on : windows-latest
30
30
steps :
31
31
- name : Harden Runner
32
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
32
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
33
33
with :
34
34
egress-policy : audit
35
35
Original file line number Diff line number Diff line change 26
26
security-events : write
27
27
steps :
28
28
- name : Harden Runner
29
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
29
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
30
30
with :
31
31
disable-sudo : true
32
32
egress-policy : block
41
41
uses : microsoft/DevSkim-Action@914fa647b406c387000300b2f09bb28691be2b6d # v1.0.14
42
42
43
43
- name : Upload DevSkim scan results to GitHub Security tab
44
- uses : github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
44
+ uses : github/codeql-action/upload-sarif@8214744c546c1e5c8f03dde8fab3a7353211988d # v3.26.7
45
45
with :
46
46
sarif_file : devskim-results.sarif
Original file line number Diff line number Diff line change 24
24
runs-on : windows-latest
25
25
steps :
26
26
- name : Harden Runner
27
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
27
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
28
28
with :
29
29
egress-policy : audit
30
30
54
54
ci_run : " false"
55
55
sarif_file : findings.sarif
56
56
- name : Upload SARIF to github
57
- uses : github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93
57
+ uses : github/codeql-action/upload-sarif@8214744c546c1e5c8f03dde8fab3a7353211988d
58
58
with :
59
59
sarif_file : findings.sarif
Original file line number Diff line number Diff line change 10
10
runs-on : ubuntu-latest
11
11
steps :
12
12
- name : Harden Runner
13
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
13
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
14
14
with :
15
15
egress-policy : audit
16
16
Original file line number Diff line number Diff line change 13
13
pull-requests : write
14
14
steps :
15
15
- name : Harden Runner
16
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
16
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
17
17
with :
18
18
egress-policy : audit
19
19
Original file line number Diff line number Diff line change 21
21
22
22
steps :
23
23
- name : Harden Runner
24
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
24
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
25
25
with :
26
26
egress-policy : audit
27
27
Original file line number Diff line number Diff line change 32
32
33
33
steps :
34
34
- name : Harden Runner
35
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
35
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
36
36
with :
37
37
egress-policy : audit
38
38
56
56
57
57
# Upload results to the Security tab
58
58
- name : Upload OSSAR results
59
- uses : github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
59
+ uses : github/codeql-action/upload-sarif@8214744c546c1e5c8f03dde8fab3a7353211988d # v3.26.7
60
60
with :
61
61
sarif_file : ${{ steps.ossar.outputs.sarifFile }}
Original file line number Diff line number Diff line change @@ -31,7 +31,7 @@ permissions:
31
31
jobs :
32
32
scan-scheduled :
33
33
if : ${{ github.event_name == 'push' || github.event_name == 'schedule' }}
34
- uses : " google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@678a866dcba398c8ed0124a09928d250f187b52a " # v1.8.4
34
+ uses : " google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@f0e6719deb666cd19a0b56bc56d01161bd848b4f " # v1.8.5
35
35
with :
36
36
# Example of specifying custom arguments
37
37
scan-args : |-
40
40
./
41
41
scan-pr :
42
42
if : ${{ github.event_name == 'pull_request' || github.event_name == 'merge_group' }}
43
- uses : " google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@678a866dcba398c8ed0124a09928d250f187b52a " # v1.8.4
43
+ uses : " google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@f0e6719deb666cd19a0b56bc56d01161bd848b4f " # v1.8.5
44
44
with :
45
45
# Example of specifying custom arguments
46
46
scan-args : |-
Original file line number Diff line number Diff line change 13
13
python-version : ["3.11.8"]
14
14
steps :
15
15
- name : Harden Runner
16
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
16
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
17
17
with :
18
18
egress-policy : audit
19
19
Original file line number Diff line number Diff line change 35
35
runs-on : windows-latest
36
36
steps :
37
37
- name : Harden Runner
38
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
38
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
39
39
with :
40
40
egress-policy : audit
41
41
Original file line number Diff line number Diff line change 36
36
runs-on : ubuntu-latest
37
37
steps :
38
38
- name : Harden Runner
39
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
39
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
40
40
with :
41
41
egress-policy : block
42
42
allowed-endpoints : >
Original file line number Diff line number Diff line change 19
19
20
20
steps :
21
21
- name : Harden Runner
22
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
22
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
23
23
with :
24
24
disable-sudo : true
25
25
egress-policy : block
Original file line number Diff line number Diff line change 13
13
14
14
steps :
15
15
- name : Harden Runner
16
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
16
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
17
17
with :
18
18
egress-policy : audit
19
19
Original file line number Diff line number Diff line change 27
27
28
28
steps :
29
29
- name : Harden Runner
30
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
30
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
31
31
with :
32
32
disable-sudo : true
33
33
egress-policy : block
Original file line number Diff line number Diff line change 32
32
33
33
steps :
34
34
- name : Harden Runner
35
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
35
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
36
36
with :
37
37
disable-sudo : true
38
38
egress-policy : block
87
87
# Upload the results to GitHub's code scanning dashboard (optional).
88
88
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
89
89
- name : " Upload to code-scanning"
90
- uses : github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
90
+ uses : github/codeql-action/upload-sarif@8214744c546c1e5c8f03dde8fab3a7353211988d # v3.26.7
91
91
with :
92
92
sarif_file : results.sarif
Original file line number Diff line number Diff line change 24
24
image : returntocorp/semgrep
25
25
steps :
26
26
- name : Harden Runner
27
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
27
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
28
28
with :
29
29
egress-policy : audit
30
30
Original file line number Diff line number Diff line change 11
11
12
12
steps :
13
13
- name : Harden Runner
14
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
14
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
15
15
with :
16
16
disable-sudo : true
17
17
egress-policy : block
Original file line number Diff line number Diff line change 33
33
34
34
steps :
35
35
- name : Harden Runner
36
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
36
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
37
37
with :
38
38
disable-sudo : true
39
39
egress-policy : block
Original file line number Diff line number Diff line change 23
23
24
24
steps :
25
25
- name : Harden Runner
26
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
26
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
27
27
with :
28
28
egress-policy : audit
29
29
Original file line number Diff line number Diff line change 23
23
runs-on : ubuntu-latest
24
24
steps :
25
25
- name : Harden Runner
26
- uses : step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9 .1
26
+ uses : step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10 .1
27
27
with :
28
28
egress-policy : block
29
29
allowed-endpoints : >
You can’t perform that action at this time.
0 commit comments